Wp Erp
Vendor:
First CVE: Jun 27, 2023 · Active for 3 years
21
Total CVEs
More Total CVEs than 95% of tracked products
5.3
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 29% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Wp Erp over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 27, 2023
3 years ago
Most Recent CVE
Jul 23, 2026
5 days ago
CVE Severity & Scoring
Wp Erp21 CVEs
67%
33%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network21 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (71.4%)
Unknown0 (0.0%)
Required6 (28.6%)
Privileges Required
Low7 (33.3%)
High7 (33.3%)
None7 (33.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-59522MEDIUM Subscriber Broken Access Control in WP ERP <= 1.17.5 versions. | Jul 23, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-31917HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in weDevs WP ERP erp allows SQL Injection.This issue affects WP ERP: from n/a thr | Mar 13, 2026 | 8.5 | 27 | NO | NO |
CVE-2024-6666HIGH The WP ERP plugin for WordPress is vulnerable to SQL Injection via the ‘vendor_id’ and 'status' parameter in all versions up to, and including, 1.13.0 due to insufficient escaping | Jul 11, 2024 | 8.8 | 25 | NO | NO |
CVE-2023-2744HIGH The ERP WordPress plugin before 1.12.4 does not properly sanitise and escape the `type` parameter in the `erp/v1/accounting/v1/people` REST API endpoint before using it in a SQL st | Jun 27, 2023 | 7.2 | 23 | NO | NO |
CVE-2025-67546MEDIUM Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in weDevs WP ERP erp allows Retrieve Embedded Sensitive Data.This issue affects WP ERP: fro | Dec 18, 2025 | 6.5 | 22 | NO | NO |
CVE-2024-12812HIGH The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 is affected by an IDOR issue where employees can man | May 15, 2025 | 7.5 | 21 | NO | NO |
CVE-2024-1173HIGH The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter | May 2, 2024 | 7.2 | 21 | NO | NO |
CVE-2024-0952HIGH The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the id parameter | Apr 9, 2024 | 7.2 | 21 | NO | NO |
CVE-2024-0913HIGH The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to time-based SQL Injection via the erp/v1/accou | Mar 29, 2024 | 7.2 | 21 | NO | NO |
CVE-2024-0608MEDIUM The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting plugin for WordPress is vulnerable to union-based SQL Injection via the 'email' par | Mar 29, 2024 | 6.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (21 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (21 CVEs).
Media Mentions
Signals from CVEs in this product scope (21 CVEs).
Top CNAs Publishing CVEs For Wp Erp
Top CWEs
Versions
No cataloged versions.